Abstract: The objective of a data-free closed-box adversarial attack is to attack a victim model without using internal information, training datasets or semantically similar substitute datasets.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results